C&CMembers
C&C

Dutch VPS and Borrowed ISP Relays Power Ranapama Infostealer C2

A single LeaseWeb VPS in the Netherlands anchors a 57-IP command-and-control network for the ranapama infostealer, with the operator hiding behind compromised Korean broadband endpoints, Belarusian mobile subscriber lines, and a factory-default TP-Link router on the Palestinian PALTEL network. The architecture is designed to make attribution and takedown significantly harder than a conventional dedicated-hosting C2 cluster. CTX Team first observed the campaign on 10 June 2026.

Jun 11, 2026, 10:46 (UTC+9)Last seenJun 11, 2026Severity98ByCTX TeamIOC58MITRE30

A Let's Encrypt certificate minted on 29 January 2026 for the domain aceinco.com — valid for exactly 89 days, hosted on a LeaseWeb Netherlands VPS at 85.17.31.111 (AS60781) — is the clearest fingerprint of operator-controlled infrastructure in a 57-IP command-and-control network assembled around the ranapama infostealer. Everything else in the observable pool appears to be borrowed: compromised Korea Telecom broadband endpoints, hijacked subscriber lines on a Belarusian mobile carrier, and at…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence